Skip to content

chore(security): fix CVEs (2026-05-12)#56

Open
Kevintjuhz wants to merge 2 commits into
developfrom
cve-fixes-2026-05-12
Open

chore(security): fix CVEs (2026-05-12)#56
Kevintjuhz wants to merge 2 commits into
developfrom
cve-fixes-2026-05-12

Conversation

@Kevintjuhz
Copy link
Copy Markdown
Member

Security CVE fixes — 2026-05-12

Automatically applied by /cve-fix. Patch and minor bumps only.

Severity Package From To CVE Summary
high @babel/plugin-transform-modules-systemjs 7.29.0 7.29.4 CVE-2026-44728 @babel vulnerability
high fast-uri 3.1.0 3.1.2 CVE-2026-6321, CVE-2026-6322 fast-uri vulnerabilities
medium @angular/ssr 19.2.24 19.2.25 CVE-2026-44437 @angular/ssr vulnerability
medium hono 4.12.15 4.12.18 CVE-2026-44455, CVE-2026-44457, CVE-2026-44458, CVE-2026-44459 hono vulnerabilities
medium ip-address 10.1.0 10.2.0 CVE-2026-42338 ip-address vulnerability

Manual review required:

Kevintjuhz and others added 2 commits May 12, 2026 14:37
- [high] @babel/plugin-transform-modules-systemjs 7.29.0 → 7.29.4 (CVE-2026-44728)
- [high] fast-uri 3.1.0 → 3.1.2 (CVE-2026-6321, CVE-2026-6322)
- [medium] @angular/ssr 19.2.24 → 19.2.25 (CVE-2026-44437)
- [medium] hono 4.12.15 → 4.12.18 (CVE-2026-44455, CVE-2026-44457, CVE-2026-44458, CVE-2026-44459)
- [medium] ip-address 10.1.0 → 10.2.0 (CVE-2026-42338)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- [high] @babel/plugin-transform-modules-systemjs 7.29.0 → 7.29.4 (override)
- [high] fast-uri 3.1.0 → 3.1.2 (override)
- [high] serialize-javascript 6.0.2 → 7.0.5 (override)
- [medium] @angular/ssr 19.2.24 → 19.2.25
- [medium] hono 4.12.15 → 4.12.18 (override)
- [medium] ip-address 10.1.0 → 10.1.1 (override)
- [medium] postcss 8.5.2 → 8.5.14 (override)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant